Various SEIM products have ways to get events from AMP, but AMP can't push the events.
Logrhythm has a beat for their Open Collector to pull AMP events into the SEIM via the API. (its all based on elastic beats)
I think Splunk and QRadar both have something similar. Here's Cisco Doc for splunk
https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215973-amp-for-endpoints-integration-with-splun.htmlYou may find some useful info and options in SecureX (dashboards/orchestration/incident managment/automated actions, etc.)